SQL Injection Vulnerability in Joomla J-CruisePortal by CMS Junkie
CVE-2019-25749
Key Information:
- Vendor
Cmsjunkie
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2019-25749?
The Joomla J-CruisePortal version 6.0.4 has a SQL injection flaw that enables authenticated attackers to execute arbitrary SQL commands. By manipulating the 'guest_adult' parameter through crafted POST requests to the cruises endpoint, attackers can potentially access sensitive database contents or alter existing records. This vulnerability poses significant risks for database integrity and confidentiality, making it crucial for users to implement immediate security measures.
Affected Version(s)
CruisePortal 6.0.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
